Privacy Policy

Last updated: 12 August 2026

1. Who is responsible

This Vibesboard service is operated by the person or company that runs this deployment, which is the data controller for the personal data described in this policy.

This deployment has not published its operator. Whoever runs it is responsible for the processing described here. If you are that operator, set the LEGAL_* environment variables documented in .env.example — a hosted service that collects personal data has to identify its controller.

This policy does not govern independent self-hosted deployments, which are operated by whoever runs them. A business using Vibesboard to communicate with its customers normally determines why those customer messages are processed; for that data we act as a processor on the business's instructions, so contact that business first about its use of your data.

2. Data we process

  • Account and workspace data, such as name, email address, memberships, roles, and authentication records.
  • Content you provide, including prompts, messages, files, agent instructions, feedback, and booking information.
  • Integration data needed to connect services such as model providers, Meta messaging products, Google Calendar, email, and object storage.
  • Technical and usage data, including timestamps, request metadata, error information, token counts, and security events. Anonymous rate-limit identifiers are HMACed before storage.

3. Why we use data

We process data to:

  • provide accounts, workspaces, agents, and integrations;
  • route requests to the model or tool provider you select;
  • secure, troubleshoot, and measure use of the service;
  • send transactional account and service communications; and
  • comply with legal obligations and enforce our terms.

Depending on the context, our legal basis is performance of a contract, our legitimate interests in operating and securing the service, consent, or compliance with law.

4. AI providers and other recipients

Content is sent to the model provider and integrations configured for the relevant workspace. We also use infrastructure, database, storage, authentication, monitoring, and email providers to operate the hosted service. We disclose only the data needed for those services and do not sell personal data.

5. International transfers

Our providers and workspace-configured integrations may process data outside your country. Where required, we use recognised safeguards for international transfers. Workspace owners are responsible for evaluating providers they choose and any additional transfer requirements that apply to them.

6. Retention

We retain account and workspace data while the hosted account is active and afterwards only as needed for backups, security, dispute resolution, or legal obligations. Workspace owners control deletion of much of their agent and conversation content. Retention by a connected third party is governed by that party's settings and policies. The deployment operator documents its applicable retention periods and handles requests to access, export, correct, or delete personal data through the contact below.

7. Security

We use access controls, tenant isolation, encryption for stored provider credentials, restricted administrative access, and automated security checks. No online service can guarantee absolute security. Please report suspected vulnerabilities through the process in our security policy.

8. Your choices and rights

Under the EU General Data Protection Regulation and equivalent local law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent. We may need to verify your identity before completing a request.

You may also complain to a data protection authorityyour local data protection authority. If you live in the EU or EEA, you can complain to the authority where you live or work.

9. Children

The hosted service is intended for businesses and is not directed to children. Do not submit children's personal data unless you have a lawful basis and all permissions required for that processing.

10. Contact and changes

For privacy questions or rights requests, contact the operator. Please include the account or workspace concerned and the type of request; we will verify identity and respond within the timeframe required by applicable law. We will update the date above when this policy changes and provide additional notice for material changes where required.